1. Who this policy covers
This policy applies to people who visit the CromLabs website, sign in to the client or administrator portal, submit a service application, book workspace or consultations, enrol in training, make a payment, or use the AI résumé assistant.
CromLabs operates from 4F4Q+H45, Katampe St, Maitama, Katampe, Abuja, Nigeria and is responsible for deciding how personal information is handled in the CromLabs service experience.
2. Information we collect
Information you provide
Depending on the service you choose, we may collect your name, email address, phone number, organisation, address, profile photograph, résumé details, education, work history, business or tax information, booking preferences, consultation notes, application answers and supporting files.
Google sign-in information
If you choose “Continue with Google”, Google may provide a unique account identifier and basic profile information such as your name, verified email address and profile image. CromLabs uses this information only to authenticate you, create or match your portal session, protect the account, and determine whether an approved administrator email may access the administrator area.
We request only the openid, email and profile scopes. CromLabs does not request access to your Gmail, Google Drive, contacts, calendar or Google password, and does not retain Google access or refresh tokens for this sign-in flow.
Payments and technical information
When you pay through Paystack, we handle transaction details such as the payer name and email, service, amount, status, channel, reference and provider fees. Paystack handles the payment method and secure checkout. We may also receive routine technical information needed to operate and secure the service, such as request time, IP-derived rate-limit information, browser or device details, security headers, error events and cookie data.
3. How we use information
- Authenticate you and maintain a secure portal session.
- Prefill forms, display your profile and preserve work you save in the portal.
- Review, price, process and follow up on applications, bookings, consultations and training.
- Verify payments, issue receipts, reconcile transactions and prevent fraud.
- Communicate service updates, respond to requests and provide operational support.
- Protect the website, enforce access controls, diagnose errors and improve usability.
- Meet legal, regulatory, accounting or public-authority obligations that apply to the requested service.
We do not sell Google user data or use it for targeted advertising. We do not allow people to read Google sign-in data unless access is necessary for security, support, legal compliance or a service you requested.
4. AI résumé processing
The AI résumé assistant is optional. It sends only the résumé summary, work experience, education and skills that you enter to Google Gemini after you actively tick the consent box. Contact fields such as your name, email, phone number, location and links remain in the browser and are not included in that Gemini request by CromLabs.
Gemini is instructed to improve clarity and structure without inventing facts. You should review every generated draft before using or submitting it. Google’s handling of information sent to Gemini is also governed by the terms and privacy notices for that Google service.
5. Browser storage, cookies and retention
The current portal stores some profile details, drafts, applications, bookings, attachments and transaction views in your browser’s local storage so they can remain available on that browser. Clearing site data, using another browser or device, or using a private browsing window may remove or hide those locally stored records.
After sign-in, CromLabs uses a signed, HTTP-only portal cookie that normally expires after eight hours. The Google OAuth state cookie used to protect the sign-in handoff expires after about ten minutes. Security and payment-provider records may be retained for as long as reasonably needed to complete the service, reconcile accounts, resolve disputes, prevent abuse and meet legal duties.
Please avoid uploading information that is not necessary for the service. Do not send passwords, complete payment-card details, patient health records or unrelated sensitive documents through general website forms.
6. When information is shared
We share personal information only when reasonably needed for the purposes described above. Recipients may include:
- Google, for Google sign-in and, only with your separate consent, Gemini résumé processing.
- Paystack, to initialise, verify and reconcile payments.
- Hosting, security and technical providers that help operate the website.
- Government registries, tax authorities, schools, financial institutions, HMOs or other service partners when the application you requested requires them and the scope is confirmed with you.
- Professional advisers, regulators, law enforcement or courts when disclosure is required or reasonably necessary to protect rights, safety and the integrity of the service.
Third-party services operate under their own terms and privacy practices. CromLabs does not authorise a third party to use Google sign-in data for advertising or unrelated purposes.
7. Security and your choices
We use measures such as encrypted HTTPS connections, signed secure cookies, OAuth state and PKCE protections, access checks, same-origin checks, rate limits, payment-webhook verification and restricted administrator access. No online system can be guaranteed completely secure, so keep your device and sign-in details protected and tell us promptly if you suspect unauthorised access.
You may use email authentication instead of Google sign-in. You can also review or revoke CromLabs access from your Google Account, clear CromLabs browser data, update your portal profile, or ask us to access, correct or delete information we control. Some records may need to be retained for payment, legal, fraud-prevention or service-completion reasons.
8. Children and changes to this policy
CromLabs is not directed to children under 13. A person who has not reached the legal age to enter a contract should use the service only with the involvement of a parent or legal guardian.
We may update this policy when the service, law or our providers change. We will publish the revised date on this page and provide a more prominent notice when a change materially affects how personal information is used.